Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade firefox-x11Upgrade firefoxUpgrade thunderbird | Nov 26, 2025 | Nov 13, 2025 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade firefox | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade firefox-debuginfoUpgrade firefox-debugsourceUpgrade firefox | Dec 9, 2025 | Nov 11, 2025 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Nov 14, 2025 | Nov 14, 2025 |
| Freebsd | — | Upgrade firefoxUpgrade firefox-esr | Dec 10, 2025 | Nov 13, 2025 |
| Mfsa2025 87 | — | Upgrade to Mozilla Firefox version 145.0 | Nov 12, 2025 | Nov 11, 2025 |
| Mfsa2025 88 | — | Upgrade to Mozilla Firefox ESR version 140.5 | Nov 12, 2025 | Nov 11, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 140.5 | Nov 17, 2025 | Nov 13, 2025 |
| Oracle_linux | — | Upgrade firefox-x11Upgrade thunderbirdUpgrade firefox | Nov 28, 2025 | Nov 11, 2025 |
| Redhat_linux | — | Upgrade firefox-debugsourceUpgrade firefox-x11No solution existsUpgrade thunderbirdUpgrade firefoxUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade thunderbird-debugsource | Nov 14, 2025 | Nov 11, 2025 |
| Rocky_linux | — | Upgrade thunderbird-debugsourceUpgrade firefox-x11Upgrade firefox-debugsourceUpgrade firefoxUpgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade firefox-debuginfo | Feb 5, 2026 | Dec 1, 2025 |
| Ubuntu | — | Upgrade thunderbird | Feb 4, 2026 | Feb 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub